Privacy Policy

Effective Date: 1st July 2025

1. Controller and Contact Information

This privacy policy applies to data processing by:

PaxUp Aviation Insights GmbH
Vorholzstr. 39
76137 Karlsruhe
Germany

Managing Director: Matthias Hunger
Commercial Register: Mannheim HRB 754629

Contact:
Email: privacy25 (at) paxup (dot) com

2. Data Processing on Our Website

2.1. Hosting, Access Data, and Security

Our website is hosted on servers provided by Scaleway S.A.S., 8 rue de la Ville l'Évêque, 75008 Paris, France, with hosting region set to Paris (EU). Website traffic is routed globally through the bunny.net network for DNS resolution, caching, DDoS protection, and firewall services.

Data processed includes:

  • IP address
  • Date and time of access
  • Accessed URL and referrer
  • Browser type and operating system
  • DNS/TLS metadata
  • Security and firewall logs

Purpose:

  • Secure and stable delivery of website content
  • Protection against attacks and abusive traffic
  • Load balancing and performance optimization
  • DNS-based hosting and availability

Legal basis: Article 6(1)(f) GDPR (legitimate interest in secure and efficient service delivery)

Data transfer: Scaleway processes data exclusively in the EU (Paris region). bunny.net routes DNS requests globally but delivers website content regionally. Personal data (e.g., from forms) is sent only to Scaleway (Paris).

Retention period: bunny.net stores access and security logs for a limited period, typically up to 7 days, unless longer retention is needed for abuse detection or diagnostics.

Encryption: All traffic to and from our website is encrypted using TLS/SSL.

2.2. Contact Form

You can contact us via a form on our website. We collect:

  • Name
  • Email address
  • Organization
  • Message
  • Optional: consent to receive our newsletter

Form data is submitted to Scaleway (Paris) and sent via Resend, an email infrastructure provider based in the USA, with delivery from EU (Ireland).

Purpose:

  • Responding to inquiries
  • Maintaining business communication
  • Sending newsletter updates (optional)

Legal basis:

  • Article 6(1)(b) GDPR (pre-contractual steps)
  • Article 6(1)(f) GDPR (legitimate interest in efficient communication)
  • Article 6(1)(a) GDPR (consent for newsletter)

Data transfer to third countries: While emails are sent from within the EU, metadata may be processed by Resend in the USA. Resend states GDPR compliance.
Privacy policy: https://resend.com/legal/privacy-policy

Retention: Contact form data is retained for up to 24 months to facilitate follow-up and future communication.

2.3. Newsletter Subscription

When you subscribe to our newsletter, we collect:

  • Email address
  • Name (optional)
  • Organization (optional)
  • IP address and subscription timestamp
  • Email interaction data (e.g., opens, clicks)

We use EmailOctopus, operated by Three Hearts Digital Ltd (UK). Data is stored in the EU (AWS infrastructure).

Purpose:

  • Delivering email updates about products, events, and services
  • Performance tracking and engagement optimization

Legal basis: Article 6(1)(a) GDPR (your consent)

Data transfer: There is no transfer to countries outside the EU/EEA. EmailOctopus confirms full GDPR compliance.
Further info: https://emailoctopus.com/legal/gdpr

Retention and deletion: Newsletter subscription data is stored for the duration of the subscription. After unsubscribing, data will remain stored in our email system (EmailOctopus) with unsubscribed status unless manually deleted. You may request full deletion at any time.
We regularly review and delete inactive unsubscribed contacts after a defined retention period (e.g., 12 months), unless further retention is required to comply with legal obligations or to document prior consent.

Withdrawal of consent: You can unsubscribe at any time via the link in each newsletter or by contacting us directly.

2.4. Embedded LinkedIn Content

We offer the option to view content from our LinkedIn company page directly on our website via embedded iframes.

Data transfer only occurs if you give consent via our cookie banner or by manually clicking the placeholder to load LinkedIn content. Before that, no connection to LinkedIn's servers is established and no personal data is transmitted.

When consent is given, LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA may process the following data:

  • IP address
  • Browser and device information
  • Referrer URL
  • Interaction with embedded content
  • Cookies or similar technologies

Purpose: Displaying professional updates and strengthening our external communications.

Legal basis: Article 6(1)(a) GDPR (your explicit consent)

Data transfer: LinkedIn processes data in the USA. Data transfers are governed by Standard Contractual Clauses (SCCs).

Withdrawal of consent: You can revoke your consent at any time using the cookie settings on our site.

3. Data Retention Summary

Data TypeRetention PeriodPurpose
Contact Form Submissions24 monthsFollow-up communication, business relationship development
Newsletter Data (EmailOctopus)While subscribed + 12 months after unsubscribingEmail delivery, consent documentation, engagement analysis
Hosting & Security Logs (bunny.net)Typically up to 7 daysWebsite security, error detection, abuse prevention

4. Your Rights under the GDPR

You have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Request erasure of your data (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent at any time (Art. 7(3))

To exercise your rights, please contact us at:
privacy25 (at) paxup (dot) com

You also have the right to lodge a complaint with your supervisory authority. For PaxUp, the competent authority is:

Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg

5. Cookies

We use a consent-based cookie banner. No non-essential cookies or third-party content are loaded unless you explicitly agree.

You can modify or withdraw your consent anytime via the cookie settings on our website.

6. Updates to This Policy

We may update this policy to reflect legal, technical or operational changes. The most recent version is always available at https://paxup.com/privacy.